







Session description It is not possible to get a publicly trusted CA to sign a certificate for a local domain (i.e. a non-publicly resolvable domain name such as router.local, printer.home, 192.168....
Requirements for HTTPS for Local Domains
When connecting to servers on their local network, users are surprised to encounter user interfaces that display errors, show insecure connections, and block some HTTP features when missing a secure context. However, obtaining PKIX certificates for those servers is difficult for a variety of reasons. This document explores requirements for authenticating local servers.
647959 - Add Honest Achmed's root certificate
RESOLVED (kathleen.a.wilson) in CA Program - CA Certificate Root Program. Last updated 2026-04-24.
Install a root CA certificate in the trust store
Enterprise environments sometimes have a local Certificate Authority (CA) that issues certificates for use within the organization. For an Ubuntu server to be functional, and to trust the hosts in ...
Certificates for localhost
Sometimes people want to get a certificate for the hostname “localhost”, either for use in local development, or for distribution with a native application that needs to communicate with a web application. Let’s Encrypt can’t provide certificates for “localhost” because nobody uniquely owns it, and it’s not rooted in a top level domain like “.com” or “.net”. It’s possible to set up your own domain name that happens to resolve to 127.0.0.1, and get a certificate for it using the DNS challenge. However, this is generally a bad idea and there are better options.

Postfix client certificate verification – Dan Langille's Other Diary
I decided to set up some of my mail servers to require certification authentication on the submission port (587). In my case, I want to forward mail from my server at home to my public servers out there on the Internet. I don’t want just anyone to be able to submit mail here, so the easiest way for me do to this was with certification.
dietrich (@burrito.space)
@why.bsky.team how locked to the http+dns+ssl nexus of publisher-centric control is atproto? i see https noted briefly in xrpc docs. how local+offline and transport agnostic can we get here? bluetooth / mdns / laser / pigeon transports possible?
The Core Tech Behind Datum's Desktop App
We built an app to expose your localhost to a public HTTPS URL, here's how it's built and what we learned along the way.

OAuth scopes (#3806) · bluesky-social/atproto@1899b1f
* style: prefix `id` and `uri` with `request` where applicable * Dynamically validate OAuth scopes * Allow configuring trusted OAuth clients * Improve client validation * Rework authorization t...
Digital Credentials · Issue #1003 · mozilla/standards-positions
Request for Mozilla Position on an Emerging Web Specification Specification title: Digital Credentials Specification or proposal URL (if available): https://wicg.github.io/digital-identities/ Expla...
Proposal: OAuth Scopes · bluesky-social atproto · Discussion #3655
Note: a more complete proposal was published in July 2025: https://github.com/bluesky-social/proposals/tree/main/0011-auth-scopes We’re continuing work on rolling OAuth out to the atproto network. ...
W3C TPAC breakouts related to content verification/authenticity: Content Authenticity and the Web github.com/w3c/tpac2024-breakouts/issues… 👀 ”discussions around a possible Authentic Web workshop sometime in 2025 have emerged in the community.” - @torgo.com Originator Profile github.com/w3c/tpac2024-breakouts/issues…
Holy fucking shit guys im a W Social trusted verifier wsocial.eu/profile/scanash.com
Scan
W Social is the biggest lie on the AT Protocol
Hey @surf.social the atproto early adopter / tech community can’t recommend you until you implement OAuth. This is a pretty big user security issue. Let us know if you need help or contract @thisismissem.social
im'bcmgs'im
surf.social looks amazing but idk about this login experience... i dont normally wanna put my password for one site into another site 🙃
Holy fucking shit guys im a W Social trusted verifier wsocial.eu/profile/scanash.com
Scan
W Social is the biggest lie on the AT Protocol